New Contributor
Posts: 1
Registered: ‎08-09-2016

Cloudera Express, FreeIPA, and Kerberos



We currently have an 10-node Cloudera instance up and running. We would like to secure it with an already-existing FreeIPA instance we have, but are uncomfortable with giving Cloudera a service principal account with account creation and changepw features (especially since the OS on the nodes is already secured via FreeIPA).


Is there a way to enable Kerberos (via FreeIPA) with Cloudera Express without having to grant the service principal those permissions?